Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack.
Drawing on telemetry from Mandiant's incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal human intervention.
Hackers build AI frameworks for widescale credential theft
Bill Toulas
- September 8, 2026
- 08:03 AM
- 0

“Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,” GTIG notes.
“While traditional script-based automation has long been a staple of threat actor operations, groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.”
- In one such incident, a financially motivated attacker compromised an organization’s cloud infrastructure and deployed an autonomous multi-agent framework.
In less than six hours, the threat actor planned, built, and deployed a mass credential-harvesting campaign using an AI coding chatbot, a prompt, and markdown agent instructions, Google says.

Source: Google
The AI agents managed the vulnerability-scanning pipeline, harvested thousands of third-party credentials, troubleshot problems in real time, rotated IP addresses, and routed attack traffic through legitimate, compromised cloud environments to evade detection.
This approach dramatically reduced “human-in-the-loop” latency and the response windows for defenders.
In another incident, the researchers found an exposed command-and-control (C2) server hosting an automated reconnaissance and credential-management framework called “Recon.”
Its files included instructions for AI agents, knowledge files, and OpenClaw artifacts related to the framework that managed in real-time more than 23,800 harvested secrets, such as API keys.

Source: Google
GTIG's report notes other examples where China-linked cyberespionage actors experimented "with AI-powered development tools to build an AI-assisted, automated exploitation and post-exploitation pipeline."
The researchers say that other espionage groups, such as the Russia-based UNC5792, integrated AI models to automate monitoring bots searching Telegram channels for information of interest to the government.
However, GTIG underlined that fully autonomous hacking has not become widespread yet, and did not observe threat actors deploying fully autonomous pipelines for zero-day discovery and network exploitation against real-world targets.
The company also noted that Gemini, its AI model, caught many of these abuses early and responded in accordance with its safety protocols, allowing Google to take additional action, disrupt the campaigns, and ban the associated accounts.
AI tool abuse has also been observed in supply-chain attacks conducted by UNC6780 (TeamPCP), Gemini AI distillation operations involving 100 million prompts, and a growing market for stolen AI account credentials and API keys.
Also, state-backed groups continue to use AI for reconnaissance, phishing, malware development, exploitation, post-exploitation, data processing, and propaganda.
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.
- September 08, 2026
- 10:55 AM
0
-
OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor
OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities.
- September 08, 2026
- 10:40 AM
0
-
Webinar: How AI broke the Pyramid of Pain

The Pyramid of Pain works on the core idea that the higher your detections are up the pyramid, the harder you are to evade. But AI has collapsed the value of the bottom layers to zero.
The latest webinar from Push Security explains how this change impacts detection and response, and what security teams can do about it.
-
Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.
- September 08, 2026
- 09:34 AM
0
-
Webinar: The forgotten Google Workspace access that can lead to a breach
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure.
- September 08, 2026
- 08:40 AM
0
-
Microsoft: Windows Server 2025 changes causing app crashes
Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes.
- September 08, 2026
- 07:57 AM
0
-
Get GPT, Gemini & Claude in one app for a one-time $99.99
ChatOn Multi-AI Assistant Premium gives new users five years of access for $99.99 (MSRP $199.99) for a limited time, putting GPT, Gemini, Claude, Sonar, and more into one AI platform.
- September 08, 2026
- 07:12 AM
0
-
220 million traveler records exposed in Vietnam-linked APIS leak
Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials.
- September 08, 2026
- 03:35 AM
0
-
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
- September 07, 2026
- 12:50 PM
0
-
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.
- September 07, 2026
- 11:39 AM
1
-
Mathspace discloses data breach affecting over 1 million people
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system.
- September 07, 2026
- 09:05 AM
0
-
Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.
- September 07, 2026
- 08:16 AM
0
-
Block ads for your whole family online for life: AdGuard is $15 today
Looking for an affordable one-time spend to block ads, trackers, and malicious sites across up to nine devices? Get this AdGuard Family Plan lifetime subscription for $14.97 (reg. $169.99) while today's price holds.
- September 07, 2026
- 08:16 AM
0
-
ChatGPT can now connect to your personal apps to mimic writing style
OpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps.
- September 07, 2026
- 06:36 AM
0
-
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.
- September 07, 2026
- 06:32 AM
0
-
ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week.
- September 07, 2026
- 06:06 AM
0
-
N-able patches max severity N-central flaw amid ongoing attacks
N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform.
- September 07, 2026
- 02:17 AM
0
-
ChatGPT Astra is now rolling out to $20 Plus subscription
OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access..
- September 06, 2026
- 09:15 PM
0
-
Attackers conceal phishing lures using invisible Unicode characters
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters.
- September 06, 2026
- 10:23 AM
0


No comments:
Post a Comment